Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,492GitHub PoC 14,286VulnCheck XDB 8,703Nuclei 4,314Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Mozilla Firefox 1.0/1.5 XBL - MOZ-BINDING Property Cross-Domain Scripting
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earl
23RISK
open ↗Exploit-DB✓ VexDay Proof
Daffodil CRM 1.5 - 'Userlogin.asp' SQL Injection
SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
sPaiz-Nuke - 'modules.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Articles module in sPaiz-Nuke allows remote attackers to inject arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
PmWiki 2.1 - Multiple Input Validation Vulnerabilities
pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms
23RISK
open ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 6.3 - 'showflat.php' SQL Injection
SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (1)
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISK
open ↗Exploit-DB✓ VexDay Proof
GNOME Evolution 2.2.3/2.3.x - Inline XML File Attachment Buffer Overflow
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a
28RISK
open ↗Exploit-DB✓ VexDay Proof
CommuniGate Pro 5.0.6 - Server LDAP Denial of Service
CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execu
28RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Database Server 9i/10g - 'XML' Local Buffer Overflow
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server
28RISK
open ↗Exploit-DB✓ VexDay Proof
AndoNET Blog 2004.9.2 - 'Comentarios.php' SQL Injection
SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary S
23RISK
open ↗Exploit-DB✓ VexDay Proof
My Little Homepage Products - BBCode Link Tag Script Injection
Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as
23RISK
open ↗Exploit-DB✓ VexDay Proof
Exiv2 - Corrupted EXIF Data Denial of Service
Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, w
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Aironet Wireless Access Points - Memory Exhaustion ARP (Denial of Service)
Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial
28RISK
open ↗Exploit-DB✓ VexDay Proof
PMachine ExpressionEngine 1.4.1 - HTTP Referrer HTML Injection
Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
KarjaSoft Sami FTP Server 2.0.1 - Remote Stack Buffer Overflow
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RISK
open ↗Exploit-DB✓ VexDay Proof
SquirrelMail 3.1 - Change Passwd Plugin Local Buffer Overflow
Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via lon
23RISK
open ↗Exploit-DB✓ VexDay Proof
CheesyBlog 1.0 - Multiple HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary we
23RISK
open ↗Exploit-DB✓ VexDay Proof
KarjaSoft Sami FTP Server 2.0.1 - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RISK
open ↗Exploit-DB✓ VexDay Proof
Phpclanwebsite 1.23.1 - SQL Injection
SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
SleeperChat 0.3f - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyBB 1.0.1/1.0.2 Notepad - 'usercp.php' HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
PixelPost 1.4.3 - User Comment HTML Injection
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
creLoaded 6.15 - 'HTMLAREA' Automated Perl
CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files,
23RISK
open ↗Exploit-DB✓ VexDay Proof
123 Flash Chat 5.0 - Remote Code Injection
Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a craft
23RISK
open ↗Exploit-DB✓ VexDay Proof
miniBloggie 1.0 - 'login.php' SQL Injection
SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
AZ Bulletin Board 1.0.x/1.1 - 'post.php' HTML Injection
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
NewsPHP - 'index.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZDatabase 2.0 - 'db_id' Remote Command Execution
Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Rockliffe MailSite 5.3.4/6.1.22/7.0.3 - HTTP Mail Management Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
BlogPHP 1.2 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.